peter bassill · operator
$ cve CVE-2026-58479 JSON

CVE-2026-58479

9.8
CRITICAL · CVSS 3.1 · EPSS 4.4% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.4% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-07-14
Last modified2026-07-14

Affected (1)

VendorProduct
dan-in-casustainable irrigation platform

References

→ the Explorer  ·  watch your stack  ·  NVD